Two things Avast documents put SecureLine in an unusual position on a leak test. The application always connects using OpenVPN, with WireGuard reserved for two particular server types, so the protocol is mostly not yours to choose. And the DNS leak prevention Avast publishes for Windows lives in Avast Antivirus rather than in the VPN, and covers IPv4. Both are worth knowing before you read a resolver line. The output describes this browser.
Avast documents its DNS leak prevention as living in Avast Antivirus and covering IPv4 on Windows, so read the resolver line knowing which products are installed here.
Read the signals once unconnected and once connected. On SecureLine the resolver line deserves the most care, because Avast documents the protection behind it as belonging to a different product.
What Avast SecureLine VPN documents about these signals
Each point below comes from Avast's own support articles for SecureLine VPN and for preventing DNS leaks.
OpenVPN by default, WireGuard in two places
Avast states that SecureLine VPN always connects using the OpenVPN protocol, and documents WireGuard as the protocol behind two particular server types: its IP Rotation servers and its Double VPN servers. Mimic is offered for countries where OpenVPN, or IPsec on a Mac, may be blocked. Which of those you connected to changes what an address lookup on your exit returns.
IP Rotation moves the address under you
Because IP Rotation is a server type rather than a setting you can forget you enabled, two runs a few minutes apart can report different addresses without the tunnel having dropped at any point. If you are comparing two readings, note which server type you connected to before treating a changed address as evidence of instability.
The Kill Switch is not available everywhere
Avast documents the Kill Switch as automatically blocking your internet connection if SecureLine VPN unexpectedly disconnects, then narrows where you can have it. On Windows and Mac it is available in Manual VPN Mode only. On Android it requires version 8.0 or later and is not available on all device types, with Huawei named as an example. Confirm you have one before reading a failed check as a kill-switch failure.
DNS leak prevention lives in the antivirus, on IPv4
Avast's own article on preventing DNS leaks states that the latest version of Avast Antivirus actively prevents them on IPv4, for the Windows versions it lists, and offers disabling Windows smart multi-homed name resolution as the alternative. So on this provider a resolver line can depend on a second product being installed, which is not how the rest of this shelf behaves.
The browser extension is not a second tunnel
Avast describes its extension as an optional installable component that lets you adjust certain aspects of SecureLine's behaviour from Chrome or Firefox. It is a control surface rather than a separate tunnel, so a WebRTC or address reading taken with it installed still describes whatever the application is doing on the machine as a whole.
Between the readings
Record a kill-switch drop on Avast SecureLine VPN
Avast documents the Kill Switch as available on Windows and Mac in Manual VPN Mode only, and on Android from version 8.0 with device exceptions. A recorded drop tells you whether you actually had one.
This does not test every server, app, device, or connection.
This does not prove anonymity.
This does not prove every security condition.
A clean result does not prove every leak is absent.
How to compare before and after on Avast SecureLine VPN
Note the address, the resolver and any IPv6 result on your ordinary connection first.
Connect with SecureLine and note the server type, since IP Rotation and Double VPN servers use a different protocol.
Rerun the same checks in the same browser, and note whether Avast Antivirus is installed on this machine.
Expect the address and resolver to change. A resolver that did not is where Avast's IPv4 DNS guidance for Windows applies.
Safe Copy limits
Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.
FAQ
Avast SecureLine VPN leak test FAQ
Which protocol does Avast SecureLine VPN use?
Avast states that SecureLine VPN always connects using the OpenVPN protocol, and documents WireGuard as the protocol behind its IP Rotation and Double VPN servers. Mimic is offered where OpenVPN or IPsec may be blocked.
Why did my address change between two runs?
If you connected to an IP Rotation server, a changed address is that server type behaving as documented rather than a sign that the tunnel dropped between the readings.
Do I have a Kill Switch on my platform?
It depends. Avast documents it for Windows and Mac in Manual VPN Mode only, and for Android from version 8.0, noting that it is not available on all device types and naming Huawei as an example.
How does Avast prevent DNS leaks?
Avast's article states that the latest version of Avast Antivirus actively prevents DNS leaks on IPv4 for the Windows versions it lists, and offers disabling Windows smart multi-homed name resolution as an alternative approach.
Does the browser extension change what this test sees?
Avast describes the extension as an optional component for adjusting certain aspects of SecureLine's behaviour from Chrome or Firefox. It controls the application rather than creating a separate tunnel of its own.
Why do my fingerprint values look unchanged?
A VPN changes the network path rather than the browser. Screen metrics, fonts and language are reported by the browser itself, so they normally read the same before and after connecting.
Other provider self-tests
The same current-session checks, walked through for another provider. Listed alphabetically; this is not a ranking or a comparison.